CVE-2018-1000410: Infoleak
An information exposure vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier, and the Stapler framework used by these releases, in core/src/main/java/org/kohsuke/stapler/RequestImpl.java, core/src/main/java/hudson/model/Descriptor.java that allows attackers with Overall/Administer permission or access to the local file system to obtain credentials entered by users if the form submission could not be successfully processed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1000410?
CVE-2018-1000410 has a medium severity level indicating a moderate risk to affected Jenkins installations.
How do I fix CVE-2018-1000410?
To resolve CVE-2018-1000410, upgrade Jenkins to version 2.146 or later, or LTS version 2.138.2 or later.
What versions are affected by CVE-2018-1000410?
CVE-2018-1000410 affects Jenkins versions 2.145 and earlier, and LTS versions 2.138.1 and earlier.
What type of vulnerability is CVE-2018-1000410?
CVE-2018-1000410 is an information exposure vulnerability that allows unauthorized access to sensitive information.
Who can exploit CVE-2018-1000410?
CVE-2018-1000410 can be exploited by attackers with Overall/Administer permissions on affected Jenkins instances.